Core Security Principles
Buy Only From Official Sources
Purchase your Trezor exclusively from trezor.io or an authorized reseller. A device bought secondhand or from an unofficial marketplace may have been tampered with before it reached you.
Verify Every Transaction on Device
Always read the recipient address and amount shown on your Trezor’s screen before pressing confirm. Never approve a transaction based solely on what your computer displays.
Keep Firmware Up to Date
Run the latest firmware to ensure you have all current security patches. Check for updates in Trezor Suite → Settings → Device and install them promptly.
Use a Strong PIN and Passphrase
Set a PIN of at least 6 digits to lock your device. For high-value holdings, enable a passphrase to create a hidden wallet that provides an additional layer of protection.
Protect Your Recovery Seed
Your 12- or 24-word recovery seed is the master key to your wallet. Anyone who obtains your seed can access your funds from any device, anywhere in the world—no PIN, no Trezor needed.- Write your seed on paper during setup. Never type it into any computer, phone, or website—not even Trezor Suite. Trezor Suite will never ask you to enter your seed.
- Store it offline. Do not photograph your seed, store it in a password manager, or keep it in cloud storage. Physical, offline storage is the safest approach.
- Keep multiple copies in separate secure locations. A single copy can be lost in a fire, flood, or theft. Two or three copies stored in geographically separate places (a home safe, a bank safe-deposit box, a trusted relative’s home) give you redundancy.
- Consider a metal backup. Paper degrades over time and is vulnerable to fire and water. Metal seed storage plates are resistant to physical damage and provide long-term durability.
Verify Your Device Before Use
Before trusting a Trezor with real funds, confirm that it is genuine and untampered:- Check that the holographic seal on the packaging is intact and shows no signs of removal or reapplication.
- When you first connect the device, Trezor Suite runs an authenticity check that cryptographically verifies the device is genuine Trezor hardware. Wait for this check to pass.
- Inspect the physical device for signs of tampering—loose casing, unexpected components, or unusual connectors.
Avoid Common Attack Vectors
Always Use Official Software
Install Trezor Suite exclusively from suite.trezor.io. Fake Trezor applications are distributed through phishing emails, search-engine ads, and unofficial app stores. A counterfeit app can intercept your seed entry or display false addresses to redirect your funds.Beware of Phishing
Attackers impersonate Trezor through emails, social-media messages, and websites that closely mimic trezor.io. They may claim your device needs immediate verification or that your funds are at risk. Trezor will never contact you by email asking for your seed, PIN, or passphrase. If you receive such a message, ignore it and report it.Never Enter Your Seed Into Any Software
Legitimate recovery only happens on the Trezor device itself—word by word, entered directly on the hardware using the device’s buttons. If any website, app, or support agent asks you to type your seed phrase into a browser or software field, you are being targeted by a scam. Stop immediately.Advanced Practices
Common Security Mistakes to Avoid
Storing your recovery seed digitally
Storing your recovery seed digitally
Saving your seed in a notes app, email draft, cloud document, or password manager exposes it to remote attackers. If any of those services are breached—or if your device is compromised by malware—your seed is stolen too. Always keep your seed on paper or metal, offline, and away from any networked device.
Confirming transactions without reading the device screen
Confirming transactions without reading the device screen
Malware on your computer can silently replace a recipient address at the moment you paste it into a send form. Your Trezor’s screen is tamper-proof and always shows the actual address it will sign for. If the address on the screen does not match your intended recipient, reject the transaction immediately.
Using an outdated firmware version
Using an outdated firmware version
Running old firmware means missing critical security patches. Attackers are aware of published vulnerabilities in older firmware versions and actively target users who haven’t updated. Check for firmware updates in Trezor Suite each time you use your device and install them promptly.